首页> 外国专利> Authentication and authorization mechanisms for Fortezza passwords

Authentication and authorization mechanisms for Fortezza passwords

机译:Fortezza密码的身份验证和授权机制

摘要

A method and apparatus that provide network access control are disclosed. In one embodiment, a network access control apparatus is configured to receive and authenticate a password that uses the “Fortezza” cryptographic protocol, and to receive and authenticate passwords of other types, to thereby selectively permit a client associated with the Fortezza password to access a protected network. A Fortezza card reader is coupled to the client and associated with a Fortezza card that contains the Fortezza password. A network access server is logically coupled to the client. An access control server is coupled logically between the client and the protected network and that controls access of the client to the protected network. A Fortezza authentication server is coupled to the access control server for communication therewith. A database is coupled to the access control server and that contains profile information associated with the user. The access control server receives, from the client, user access information associated with a particular user of the client; determining, based on the user access information and a database, a type of a password associated with the user; when the password type is FORTEZZA, requesting authentication of the password from a Fortezza server; granting the client access to the network when the Fortezza server approves the password; and when the password type is any type other than FORTEZZA, requesting authentication of the password from an authentication process that is associated with that password type.
机译:公开了一种提供网络访问控制的方法和装置。在一个实施例中,网络访问控制装置被配置为接收和认证使用“ Fortezza”密码的密码。加密协议,并接收和认证其他类型的密码,从而有选择地允许与Fortezza密码关联的客户端访问受保护的网络。 Fortezza读卡器耦合到客户端,并与包含Fortezza密码的Fortezza卡关联。网络访问服务器在逻辑上耦合到客户端。访问控制服务器逻辑上耦合在客户端和受保护网络之间,并控制客户端对受保护网络的访问。 Fortezza身份验证服务器耦合到访问控制服务器以进行通信。数据库耦合到访问控制服务器,该数据库包含与用户关联的配置文件信息。访问控制服务器从客户端接收与客户端的特定用户相关联的用户访问信息;根据用户访问信息和数据库,确定与用户关联的密码的类型;当密码类型为FORTEZZA时,请求Fortezza服务器对密码进行身份验证;当Fortezza服务器批准密码时,授予客户端访问网络的权限;当密码类型是FORTEZZA以外的任何其他类型时,请从与该密码类型相关联的认证过程中请求密码的认证。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号